This Annex 2 is attached to and forms part of the Data Processing Addendum (DPA) between Symbol Security, Inc. (“Symbol”) and the Partner. It provides the required advance notification of third-party sub-processors engaged by Symbol in the delivery of the Services.
1. General Authorization
The Partner grants Symbol a general authorization to engage the Sub-processors listed below, as well as new Sub-processors, in accordance with Section 4 of the DPA. Symbol shall perform due diligence to ensure each Sub-processor provides a level of data protection and security consistent with Symbol’s obligations under the DPA.
2. Current Sub-processors
The following is the initial list of sub-processors authorized to process Personal Data as of the Last Updated date of the DPA:
| Sub-processor Name | Service Provided | Processing Location (Region) |
|---|---|---|
| Google Cloud Platform (GCP) | Core Application and Data Hosting | United States (e.g., GCP East) |
| Google Cloud Platform (GCP) | Core Application and Data Hosting | Brussels, Belgium (EU Node) |
| Amazon Dedicated Server | Transactional and Service-Related Email Sending | United States |
| SendGrid | Transactional and Service-Related Email Sending | United States |
3. Notification of New Sub-processors
Symbol shall update the master list of Sub-processors at symbolsecurity.com/legal/sub-processors with reasonable advance notice of any new appointments. By entering into the DPA, the Partner agrees that Symbol’s update of this list shall constitute the required notification.
4. Location of Processing Clarification (Refers to Annex 1, Section C)
As stated in Annex 1, Personal Data is hosted in Symbol’s United States infrastructure by default. The Brussels, Belgium (EU) node is used only upon the express instruction or technical selection by the Data Controller (Partner) for specific accounts.